TL;DR
Senior Offensive Security Engineer (Web3, Fintech): Managing and improving the security posture of a leading crypto derivatives exchange with an accent on bug bounty program management, internal penetration testing, and red/purple team exercises. Focus on conducting security research, application security reviews, and incident investigation in a high-threat, low-latency environment.
Location: Work from home with a Beyond Border Remote Working policy, allowing work from away from your home country.
Company
hirify.global is a globally leading exchange for crypto derivatives, offering a professional-grade trading platform with an impeccable security record since 2014.
What you will do
- Manage the bug bounty program, reviewing reports and collaborating with engineering for fixes.
- Review external penetration test outcomes, replicating issues and working with engineering to resolve findings.
- Conduct internal penetration tests on software and infrastructure stacks.
- Perform Red and Purple team exercises to test monitoring capabilities.
- Engage in security research & threat intelligence, coordinating with security response.
- Perform application security & code reviews and provide internal training to engineers.
- Participate in incident response to triage and investigate security issues.
Requirements
- 5+ Years in Information Security.
- Proven expertise in offensive security through certifications, recognition, or referees.
- Strong communication skills and a proactive work ethic.
- Candidates with less experience will be considered for an Offensive Security Engineer position.
Nice to have
- Experience with Kubernetes, Istio, Envoy, and AWS cloud platform.
- Experience with GitHub CI/CD / Actions and/or ArgoCD.
- Experience with derivatives and cryptocurrency.
- Development expertise in Go.
Culture & Benefits
- Work from home to achieve work-life balance.
- 25 days of annual leave, plus public holidays and various other leaves.
- Top-tier and comprehensive medical, dental, and vision policy for you and your dependents.
- Professional development allowance to support career advancement.
- Access to annual wellness benefits for physical and mental growth.
- Beyond Border Remote Working policy for flexibility to work from different countries.
- Team building & offsite events to connect the global team.
- Life insurance coverage for family safety.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →